7.2
CVSSv2

CVE-2002-0246

Published: 29/05/2002 Updated: 11/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint.

Vulnerable Product Search on Vulmon Subscribe to Product

caldera unixware 7.1.1

Exploits

source: wwwsecurityfocuscom/bid/4060/info UnixWare is a commercially available Unix Operating System It was originally developed by SCO, and is now distributed and maintained by Caldera A format string vulnerability in the locale subsystem could lead to a user gaining elevated privileges A local user could potentially supply malicious ...